mirror of
https://github.com/CVEProject/cvelist.git
synced 2025-08-04 08:44:25 +00:00
71 lines
2.5 KiB
JSON
71 lines
2.5 KiB
JSON
![]() |
{
|
||
|
"CVE_data_meta": {
|
||
|
"ASSIGNER": "productcert@siemens.com",
|
||
|
"ID": "CVE-2019-18341",
|
||
|
"STATE": "PUBLIC"
|
||
|
},
|
||
|
"data_format": "MITRE",
|
||
|
"data_version": "4.0",
|
||
|
"data_type": "CVE",
|
||
|
"affects": {
|
||
|
"vendor": {
|
||
|
"vendor_data": [
|
||
|
{
|
||
|
"vendor_name": "Siemens AG",
|
||
|
"product": {
|
||
|
"product_data": [
|
||
|
{
|
||
|
"product_name": "SiNVR 3 Central Control Server (CCS)",
|
||
|
"version": {
|
||
|
"version_data": [
|
||
|
{
|
||
|
"version_value": "all versions"
|
||
|
}
|
||
|
]
|
||
|
}
|
||
|
},
|
||
|
{
|
||
|
"product_name": "SiNVR 3 Video Server",
|
||
|
"version": {
|
||
|
"version_data": [
|
||
|
{
|
||
|
"version_value": "all versions"
|
||
|
}
|
||
|
]
|
||
|
}
|
||
|
}
|
||
|
]
|
||
|
}
|
||
|
}
|
||
|
]
|
||
|
}
|
||
|
},
|
||
|
"problemtype": {
|
||
|
"problemtype_data": [
|
||
|
{
|
||
|
"description": [
|
||
|
{
|
||
|
"lang": "eng",
|
||
|
"value": "CWE-287: Improper Authentication"
|
||
|
}
|
||
|
]
|
||
|
}
|
||
|
]
|
||
|
},
|
||
|
"description": {
|
||
|
"description_data": [
|
||
|
{
|
||
|
"lang": "eng",
|
||
|
"value": "A vulnerability has been identified in SiNVR 3 Central Control Server (CCS) (all versions), SiNVR 3 Video Server (all versions). The SFTP service (default port 22/tcp) of the SiNVR 3 Central Control Server\n(CCS) contains an authentication bypass vulnerability.\n\nA remote attacker with network access to the CCS server could \nexploit this vulnerability to read data from the EDIR directory\n(for example, the list of all configured stations).\n"
|
||
|
}
|
||
|
]
|
||
|
},
|
||
|
"references": {
|
||
|
"reference_data": [
|
||
|
{
|
||
|
"refsource": "CONFIRM",
|
||
|
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-761617.pdf"
|
||
|
}
|
||
|
]
|
||
|
}
|
||
|
}
|